DFSP # 422 - EVTX Express: Cracking into Windows Logs Like a Pro

DFSP # 422 - EVTX Express: Cracking into Windows Logs Like a Pro

Today I'm talking Windows forensics, focusing on Windows event logs. These logs are very valuable for fast triage, often readily available in your organization's SIEM. But have you ever wondered about the processes enabling this quick access? Not only are the logs automatically collected and fed into the appliance, but they are also formatted and normalized for easy data searchability. This is crucial, as the logs are originally in a complex format challenging to natively interpret. Now, picture a scenario where event logs are inaccessible through a security appliance—enter this week's topic: EVTX analysis options. Don't be caught unprepared.

Tämä jakso on lisätty Podme-palveluun avoimen RSS-syötteen kautta eikä se ole Podmen omaa tuotantoa. Siksi jakso saattaa sisältää mainontaa.

Jaksot(498)

Suosittua kategoriassa Tiede

rss-poliisin-mieli
rss-mita-tulisi-tietaa
docemilia
tiedekulma-podcast
utelias-mieli
rss-luontopodi-samuel-glassar-tutkii-luonnon-ihmeita
rss-hereilla
rss-ylistys-elaimille
hippokrateen-vastaanotolla
rss-tervetta-skeptisyytta
rss-duodecim-lehti
rss-bios-podcast
rss-tiedetta-vai-tarinaa
rss-sotepodi-ratkaisuja-hyvinvointiin
rss-kasvikutsut
rss-totuuden-liepeilla
mielipaivakirja
rss-ammamafia
filocast-filosofian-perusteet